Skip to content

AI for Office

AI for Office puts a branded, policy-controlled AI assistant directly inside Microsoft Office for your customers’ end-users – in Excel, Word, PowerPoint, and Outlook. It’s primarily a co-pilot your clients use in their own documents, governed by the same policy and data-protection controls as the rest of Breeze. In Outlook, the same add-in also has a technician side – see Working tickets from Outlook.

End-users open the add-in task pane, sign in with their existing Microsoft identity, and chat with the assistant without leaving their document. You decide which customers can use it, what it’s allowed to do, and how much it can spend.

AI for Office is a per-partner entitlement controlled by the platform operator. It is off by default for every partner, so you’re never billed for AI usage by partners you haven’t explicitly enabled.

The entitlement is granted by the operator, not self-served – a partner cannot turn it on for themselves. When a partner is disabled, the feature is unavailable across all of their customer organizations, and disabling a partner cuts off live sessions immediately, not just new ones.

Once your partner is entitled, you configure AI for Office per customer organization through its org policy. The policy controls who can use the assistant and what it’s allowed to do.

Setting What it controls
Enabled Master on/off for this organization
User access Everyone in the customer’s Microsoft tenant, or a selected list of users
Write mode Whether the assistant can edit documents (read/write) or only read and inspect (read-only)
Write approval Whether each edit must be approved by the user, or applies automatically
Data-loss protection Redaction rules that strip sensitive data (such as PII) before it leaves the document
Budgets Optional daily and monthly spend caps
Rate limits Per-user and per-organization message limits
Retention How long chat history is kept
Branding A display name and logo shown to end-users

Each customer organization must be mapped to its Microsoft Entra tenant so sign-ins resolve to the right org. This mapping is the foundation of tenant isolation and is set once per organization. Creating or changing a tenant mapping requires multi-factor authentication.

  1. Open the AI for Office admin area and select the customer organization.
  2. Enter the customer’s Entra tenant ID (Breeze suggests it automatically if you already have a Microsoft 365 connection for that customer).
  3. Grant the required admin consent for the add-in on the customer’s tenant.
  4. Enable the org policy and set access, write mode, DLP, and budgets.
  1. The end-user opens the Breeze add-in’s task pane in Excel, Word, PowerPoint, or Outlook.
  2. The add-in uses their existing Microsoft identity – no separate Breeze login.
  3. Breeze verifies the identity, maps the Microsoft tenant to the correct organization, and checks that the partner is entitled, the org policy is enabled, and the user is allowed.
  4. The user starts chatting. Edits and document actions follow the org’s write-mode and approval settings, and responses pass through the org’s data-loss protection rules.

The admin area gives you operational visibility for each customer organization:

  • Onboarding status – a per-org checklist showing whether the tenant is mapped, consent is granted, and the policy is enabled.
  • Sessions – which end-users are using the assistant, in which Office host, with message and token counts.
  • Usage and cost – monthly usage per user with token counts and cost, exportable as CSV for resale and accounting.

Working Tickets from Outlook (Technicians)

Section titled “Working Tickets from Outlook (Technicians)”

The Outlook add-in has a second face. When the person signed in is one of your technicians rather than a customer end-user, the same task pane opens as a ticketing console instead of the client chat – so a technician can work a customer email without leaving Outlook.

On an open received message, the pane shows, top to bottom:

  • Context card – the customer organization resolved from the sender (by email domain, or an exact contact match), with a one-line summary of sites, devices, and open tickets. If nothing matched, an organization search box lets the technician pick one. If several contacts share the address, it asks which one – nothing is guessed.
  • Ticket list – the ticket already linked to this email thread if there is one, plus recent open tickets for that organization, flagged when the ticket’s requester is this sender.
  • Link email to ticket – attach the message to a ticket as either a public comment (the customer’s own words, visible to them) or an internal note.
  • Create ticket from this email – subject and description are prefilled from the email immediately and then improved by an AI draft. Choose whether the requester is the raw sender, an existing portal contact, or a new contact.
  • Time tracking – start or stop the technician’s timer against the selected ticket, or log time manually with a description and an optional billable flag.
  1. Register the add-in in your own Microsoft Entra tenant and deploy it to your technicians through Microsoft 365 centralized deployment (sideload it first if you just want to try it).
  2. In Outlook, open the Breeze pane and choose Technician sign-in.
  3. Sign in with the technician’s Breeze email, password, and MFA code. A technician without MFA enrolled is asked to enrol in Breeze first.

That links the technician’s Microsoft identity to their Breeze account once. From then on it is the Microsoft identity that authorizes the pane, so nothing about which pane a person gets is left to them: a linked identity gets the technician console, an unlinked one falls through to the customer assistant, and a revoked one is refused outright.

Manage the links at Settings → Outlook Add-in Bindings. The list shows each technician, their Microsoft tenant, and when the link was verified; revoking one signs that technician out of the add-in everywhere immediately. Viewing or revoking requires partner-level access across all organizations plus a multi-factor step-up. Links also invalidate themselves when a user is deactivated, a partner is suspended, or a password reset forces a logout.

  • One ticket per email message. Linking the same message again returns the ticket it already created; a message attached to a different ticket reports the conflict rather than duplicating.
  • A closed ticket cannot be appended to. The pane offers a linked follow-up instead, which must stay in the same organization.
  • The technician’s own permissions still apply. No ticket-write access means no create or link; no time-entry access hides the time widget; organization and site restrictions are unchanged.
  • The AI draft is optional. It needs the partner’s AI for Office entitlement, and it is skipped when a data-protection policy blocks the email content or the model is unavailable – the form then falls back to a plain prefill from the subject and body. Ticket creation never waits on AI, and the AI never chooses the organization, contact, or ticket for you.
  • Future replies only auto-attach if you have a connected ticket mailbox. Linking from a technician’s personal mailbox will not thread later replies, and the pane says so rather than letting you assume otherwise.
  • Compose mode and shared mailboxes are not supported yet, and older Outlook builds fall back to subject-and-sender matching with a banner.

Viewing AI for Office configuration requires organization read access; changing org policies and templates requires organization write access. Tenant-mapping changes additionally require multi-factor authentication. The per-partner entitlement is operator-only.